[Samba] Problem with group/user modification

Isidoros Kanakis kanakis at upstreamsystems.com
Tue Oct 14 12:46:36 GMT 2003


Hi people!

I have a samba-PDC (samba-3.0.0-2) based on LDAP backend 
(ldapsam_compat). The PDC is working fine, with machines
added automatically to the domain, printing with up/downloading
of printer drivers in place and correct display of users/groups
in the windows properies box.

However when I try to change the group membership, I get a
strange error:

   ldapsam_search_one_group: Problem during the LDAP search: LDAP error: 
  (Insufficient access)kanakis opened file test1
read=Yes write=No (numopen=2)
[2003/10/14 15:38:34, 2] passdb/pdb_ldap.c:ldapsam_search_one_group(1597)
   ldapsam_search_one_group: searching 
for:[(&(objectClass=sambaGroupMapping)(sambaSID=S-1-5-21-644945029-4113388124-2141
564926-3034))]
[2003/10/14 15:38:34, 0] lib/smbldap.c:smbldap_open(799)
   smbldap_open: cannot access LDAP when not root..
[2003/10/14 15:38:34, 1] lib/smbldap.c:smbldap_retry_open(888)
   Connection to LDAP Server failed for the 1 try!
[2003/10/14 15:38:34, 0] passdb/pdb_ldap.c:ldapsam_search_one_group(1612)
   ldapsam_search_one_group: Problem during the LDAP search: LDAP error: 
  (Insufficient access)kanakis closed file test1



It is strange because according to the ldap logs, no attempt is beeing 
made to access "objectClass=sambaGroupMapping". (3034 is the RID of user
kanakis)

The same error appears when I modify  file permissions, but
samba still sets the new permission set.

Has anybody an idea what this
"smbldap_open: cannot access LDAP when not root.."
is all about?


Thx in advance!
-- 
Isidoros Kanakis
Systems Engineer
kanakis at upstreamsystems.com

Upstream S.A.
Athanasaki 3, Ambelokipi,
Athens 11526, Greece
Tel: +30 210 6985897
Fax: +30 210 6983984
http://www.upstreamsystems.com





More information about the samba mailing list